Courseiva

CCSP Legal, Risk, and Compliance Practice Question

Under GDPR, what is the maximum time allowed for a data controller to notify the supervisory authority of a personal data breach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

72 hours

GDPR Article 33 requires notification within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to rights and freedoms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    7 days

    Why it's wrong here

    GDPR sets a 72-hour notification deadline, so 7 days exceeds the permitted maximum. It is tempting because some sectoral or national breach rules use longer windows, but the GDPR itself specifies 72 hours for controllers notifying the supervisory authority.

  • ✗

    24 hours

    Why it's wrong here

    GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, so 24 hours is too short. It is tempting because shorter deadlines appear stricter, but the regulation fixes 72 hours; 24 hours is not the GDPR limit.

  • ✓

    72 hours

    Why this is correct

    GDPR Article 33 requires controllers to notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in risk to individuals' rights and freedoms.

  • ✗

    48 hours

    Why it's wrong here

    GDPR mandates notification within 72 hours of awareness, so 48 hours is shorter than the actual requirement. It is tempting because 48 hours sounds like a plausible regulatory deadline, but the regulation specifies 72 hours, not 48.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.